Outreach policy · v1 · effective 28 July 2026

We sell consent software.
So ask how we got your address.

Every compliance vendor in India will tell you they respect your data. Here is the test: ask them where their prospect list came from, what the lawful basis is for each contact, and whether they can show you their own suppression register. This page is our answer, and the register is a real table in a real database.

The short version

We contact organisations at role mailboxes (info@, compliance@) that the organisation itself publishes, or people whose professional details they made public. We never buy lists. We send at most two messages, ever. One "stop" — or simply not replying to the second — ends it permanently. We do not cold-call or cold-SMS at all.

1 · Where contact details come from

Three sources, and every record in our system stores which one it came from, the page or document it came from, and the date — provenance is a mandatory field, not an optional note.

  • Public regulatory registers — lists that regulators publish under a legal obligation (CERT-In's empanelled auditors, RBI's register of NBFCs, IRDAI's licensed insurers). Organisation-level information about organisations.
  • An organisation's own website — the contact address a firm publishes on its own contact page, read as published.
  • Details a person chose to make public about their professional role, or gave us directly at an event or through a form on this site.

2 · The lawful basis, stated per contact

Every contact record carries its basis, and our system will not store one without it:

  • Not personal data — a shared functional mailbox belongs to the organisation, not to an individual, so the DPDP Act's personal-data rules are not engaged. This is the overwhelming majority of our outreach.
  • Publicly available, published by the person themselves — under §3(c)(ii), personal data a person has made public about their own professional role (their own bio, listing, or profile) falls outside the Act. We use it only in the form it was published, and never enrich it into a profile.
  • An organisation's own published contact page — we are taking advice on whether §3(c)(ii)'s carve-out extends to a role-based address an organisation itself chose to publish, as distinct from one an individual published about themselves, and would rather say the basis is under review than assert a citation we are not certain covers it. See our privacy notice, §2.
  • Voluntarily provided — you gave it to us for this purpose (§7(a)).

3 · What we will never do

  • Buy or scrape a contact database. Bought lists carry no verifiable provenance, which is precisely the disease we sell the cure for.
  • Cold-call or cold-SMS you. Not one call, not one message.
  • Send sales mail to a grievance officer's inbox. That channel exists so people can complain about data handling. Using it to sell would be an abuse of it.
  • Scan your systems uninvited and send you the results as a sales hook. Our scanner runs when you ask it to. Finding a problem is not a licence to frighten you with it.
  • Work around a website's access controls — robots.txt, bot protection, rate limits. If a registry blocks automated access, a human downloads it or we do without.

4 · Two messages, then silence

One message, and at most one follow-up. That cap is not a guideline our sales team tries to remember — it is a database constraint. A third message to the same organisation on the same channel is rejected by the system before it can be composed. If neither message interests you, you will not hear from us again.

5 · Stopping us, permanently

Reply with "stop" to any message, or write to hello@consentree.in. We add the address, the domain, or the whole organisation — your choice — to a suppression register that has no expiry and no exceptions. We honour it whether or not the law requires it of us, and we do not ask you to confirm twice.

6 · Why this page exists before the law requires it

The DPDP Rules commence in stages, and the obligations that would govern outreach like ours are not fully in force until 13 May 2027. We are not waiting. Contacts collected loosely today would still be sitting in our database in 2027 — that is exactly the consent debt we help clients dig out of, and we are not going to create our own while telling you not to.

7 · Hold us to it

If we contact you and you want to see the record — where the address came from, which basis we recorded, when, and every message we have sent you — ask, and we will show you that record. If we have got something wrong, tell us and we will fix it and say so. Applying our own product to our own conduct is the only demonstration that means anything.